SECURITY & TRUST

Designed for evidence.
Built for accountability.

Carta's foundation is structured for tenant isolation, least privilege, auditable changes and SOC 2 readiness. Readiness is not the same thing as an independent SOC 2 attestation.

01

Tenant-scoped access

Organizations, locations and users remain scoped. Role defaults can be overridden with explicit user permissions while preserving a deny-by-default model.

02

Database isolation

PostgreSQL row-level security, separate runtime identities and intentionally narrow public functions reduce cross-tenant exposure risk.

03

Immutable provenance

Source identity, retrieval timestamp, content hashes and original object references create a durable chain from displayed facts back to evidence.

04

Controlled ingestion

Public-source fetches are allowlisted and designed to reject private networks, metadata endpoints, unsafe redirects and uncontrolled response sizes.

05

Audited administration

High-risk actions belong behind explicit permissions and audit records. Arbitrary browser SQL is intentionally excluded from the customer admin surface.

06

SOC 2 readiness

The data model includes access reviews, incidents, evidence and retention controls. Formal compliance still requires operating evidence and an independent audit.